Soru

Zorluk: ZorThreat Detection and Vulnerability Management

A logistics company coordinates delivery routes using an application hosted on Amazon EC2 instances. The security team needs to implement a solution that continuously monitors the environment for active threats, such as instances communicating with known malicious command-and-control servers or performing unauthorized API actions. This monitoring must be performed without installing software agents or affecting application performance. Which AWS service should be used to meet these requirements?

  1. Amazon GuardDutyCevap
  2. B
    Amazon Inspector
  3. C
    AWS CloudTrail
  4. D
    Amazon CloudWatch

Cevap

Amazon GuardDuty
Amazon GuardDuty is correct because it is a threat detection service that continuously monitors for malicious activity and unauthorized behavior. It analyzes foundation data sources such as VPC Flow Logs, DNS logs, and AWS CloudTrail management events without requiring agent installation, ensuring zero impact on application performance.

Adım Adım Çözüm

1
Identify the primary requirement: continuous monitoring for active threats (such as communication with command-and-control servers) without installing agents.
Determine that the required capability is intelligent threat detection rather than host vulnerability scanning.
Vulnerability scanning (like Amazon Inspector) checks for security weaknesses, while threat detection identifies active malicious activity.
2
Analyze the constraint: no software agents must be installed and there must be no performance impact on workloads.
Identify AWS services that analyze logs at the account and network infrastructure level rather than running on the OS.
Amazon GuardDuty operates completely out-of-band by analyzing logs like VPC Flow Logs and DNS logs directly from the AWS infrastructure.
3
Evaluate the choices to find the service that matches intelligent, agentless threat detection.
Select Amazon GuardDuty as the correct service.
Amazon GuardDuty uses threat intelligence and machine learning to detect anomalies and malicious behavior without agents.

Anahtar Kavram

Amazon GuardDuty is a managed threat detection service that continuously monitors for malicious activity and unauthorized behavior in your AWS accounts and workloads by analyzing data sources like CloudTrail, VPC Flow Logs, and DNS logs.
Tahmini Süre:1m 30s
Bu soruyu puanla